Moderate: apr security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:7711", "synopsis": "Moderate: apr security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for apr.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The Apache Portable Runtime (APR) is a portability library used by the Apache HTTP Server and other projects. It provides a free library of C data structures and routines.\n\nSecurity Fix(es):\n\n* apr: integer overflow/wraparound in apr_encode (CVE-2022-24963)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2169465", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2169465", "description": ""}], "cves": [{"name": "CVE-2022-24963", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-24963", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-05-10T14:33:09.148442Z", "rpms": {"Rocky Linux 9": {"nvras": ["apr-0:1.7.0-12.el9_3.ppc64le.rpm", "apr-0:1.7.0-12.el9_3.s390x.rpm", "apr-0:1.7.0-12.el9_3.src.rpm", "apr-debuginfo-0:1.7.0-12.el9_3.ppc64le.rpm", "apr-debuginfo-0:1.7.0-12.el9_3.s390x.rpm", "apr-debugsource-0:1.7.0-12.el9_3.ppc64le.rpm", "apr-debugsource-0:1.7.0-12.el9_3.s390x.rpm", "apr-devel-0:1.7.0-12.el9_3.ppc64le.rpm", "apr-devel-0:1.7.0-12.el9_3.s390x.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A significant security patch has been rolled out for Rocky Linux 9, tackling vulnerabilities associated with potential integer overflow scenarios.. Rocky Linux Security Update, Apache Portable Runtime, Security Fixes. .LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.